Detailed analysis of captured phishing page
Used to detect similar phishing pages based on HTML content
| Algorithm | Hash Value |
|---|---|
|
CONTENT
TLSH
|
T18563A4319500DC6B41DB96C89632422A32E59385DA234789FBF487E9EF9FDF8CC36494 |
|
CONTENT
ssdeep
|
768:5asIx/j2ZELk+Cupoo/96LxCn2cCCqnlBInii1nbkKhfInfUf7Yo:5asIxs+Cl0FMQ7Yo |
Used to detect visually similar phishing pages based on screenshots
| Algorithm | Hash Value |
|---|---|
|
VISUAL
pHash
|
82a0407dfd577c56 |
|
VISUAL
aHash
|
c07f64ffff00003c |
|
VISUAL
dHash
|
b68bcd542f33d4d4 |
|
VISUAL
wHash
|
007f64ffff00183c |
|
VISUAL
colorHash
|
060000001c0 |
|
VISUAL
cropResistant
|
66caa9cdd84c270f,f0cca28e8ea2ccf0,f0ccb24e4caaccf0,f0ccb28e8ea2ccf0,f0cca2684c8ac4f0,b594000000000000,402ca2a22fc080c2,3cdedebc3461ddb1,7f3f0f0383e6f684,9f9c9e0b3763e5c4,b666800338868890,0850334555d4d4d5 |
Victim enters username and password into fake login form. Credentials are captured via JavaScript and exfiltrated to attacker's server in real-time.
Malicious code is obfuscated using 87 techniques to evade detection by security scanners and make reverse engineering more difficult.